IP Library Granted Patent US 8,898,464
Granted Patent B2
US 8,898,464 · App. 13/910,798 · Granted Nov 25, 2014

Systems and methods for secure workgroup management and communication

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,898,464
App. No.
13/910,798
Granted
Nov 25, 2014
Kind
B2
Abstract

A secure data parser is provided that may be integrated into any suitable system for securely storing and communicating data. The secure data parser may split or share a data set into multiple portions that are stored or communicated distinctly. Encryption of the original data, the portions of data, or both may be employed for additional security. The secure data parser may be used to protect data in motion by splitting an original data set into portions of data that may be communicated using one or more communications paths. Secure workgroup communication is supported through the secure distribution and management of a workgroup key for use with the secure data parser.

Claims (37)

1. A method for secure workgroup communication, the method comprising:

receiving, at a first workgroup client, an encrypted message from a workgroup key server, wherein the encrypted message comprises a workgroup key, a workgroup key version number, and a time to live (TTL) value for the workgroup key; and

initiating a communication session with a second workgroup client, wherein initiating the communication session comprises:

determining, at the first workgroup client, if the workgroup key is expired based, at least in part, on the TTL value for the workgroup key;

in response to determining that the workgroup key is expired, checking the availability of a new workgroup key from the key server;

in response to determining that the workgroup key is not expired, sending, to the second workgroup client, a plurality of share headers, wherein the share headers include the workgroup key and the workgroup key version number; and

verifying, at the second workgroup client, that the second workgroup client's workgroup key version matches the first workgroup client's workgroup key version.

2. The method of claim 1 further comprising generating the plurality of share headers before sending the plurality of share headers, wherein generating the plurality of share headers comprises distributing the workgroup key into the plurality of share headers using a secret sharing scheme.

3. The method of claim 1 wherein the encrypted message is encrypted under a symmetric cipher using the first workgroup client's secret key.

4. The method of claim 1 wherein the encrypted message is encrypted under an asymmetric cipher using the first workgroup client's public key.

5. The method of claim 1 wherein the share headers additionally include a workgroup identifier, the method further comprising verifying, at the second workgroup client, that the workgroup identifier is valid for a workgroup to which the second workgroup client belongs.

6. The method of claim 1 further comprising:

receiving, at the first workgroup client, a workgroup key update message, the workgroup key update message including a new workgroup key, a new workgroup key version number, and a new TTL value for the new workgroup key; and

updating, at the first workgroup client, a workgroup key refresh alarm based, at least in part, on the new TTL value.

7. The method of claim 6 wherein updating the workgroup key refresh alarm comprises setting the workgroup key refresh alarm to the current time plus the new TTL value.

8. The method of claim 1 , wherein the share headers are associated with a plurality of shares stored at two or more different locations.

9. The method of claim 8 , wherein the shares comprise a substantially random distribution of data from a data set.

10. The method of claim 9 , wherein restoring the data set requires at least a minimum number that is less than all of the data portions.

11. A system for secure workgroup communication, the system comprising:

a first workgroup client configured to:

receive, using processing circuitry, an encrypted message from a workgroup key server, wherein the encrypted message comprises a workgroup key, a workgroup key version number, and a time to live (TTL) value for the workgroup key; and

initiate a communication session with a second workgroup client, wherein the first workgroup client is configured to:

determine if the workgroup key is expired based, at least in part, on the TTL value for the workgroup key;

in response to determining that the workgroup key is expired, check the availability of a new workgroup key from the key server;

in response to determining that the workgroup key is not expired, send, to the second workgroup client, a plurality of share headers, wherein the share headers include the workgroup key and the workgroup key version number; and

a second workgroup client configured to verify that the second workgroup client's workgroup key version matches the first workgroup client's workgroup key version.

12. The system of claim 11 wherein the first workgroup client is configured to generate the plurality of share headers by distributing the workgroup key into the plurality of share headers using a secret sharing scheme.

13. The system of claim 11 wherein the encrypted message is encrypted under a symmetric cipher using the first workgroup client's secret key.

14. The system of claim 11 wherein the encrypted message is encrypted under an asymmetric cipher using the first workgroup client's public key.

15. The system of claim 11 wherein the share headers additionally include a workgroup identifier, the second workgroup client further configured to verify that the workgroup identifier is valid for a workgroup to which the second workgroup client belongs.

16. The system of claim 11 wherein the first workgroup client is configured to:

receive a workgroup key update message, the workgroup key update message including a new workgroup key, a new workgroup key version number, and a new TTL value for the new workgroup key; and

update a workgroup key refresh alarm based, at least in part, on the new TTL value.

17. The system of claim 16 wherein the first workgroup client is configured to update the workgroup key refresh alarm by setting the workgroup key refresh alarm to the current time plus the new TTL value.

18. The system of claim 11 , wherein the share headers are associated with a plurality of shares stored at two or more different locations.

19. The system of claim 18 , wherein the shares comprise a substantially random distribution of data from a data set.

20. The system of claim 19 , wherein restoring the data set requires at least a minimum number that is less than all of the data portions.

Assignments (4)
RELEASE OF SECURITY INTEREST Recorded Sep 30, 2022
From: GYENES, ANDY; AUBER INVESTMENTS LTD.; SIMONS, BARBARA; BLT1 C/O FAMILY OFFICE SOLUTIONS; O'REILLY, COLIN; COOPER ROAD LLC.; COYDOG FOUNDATION C/O FAMILY OFFICE SOLUTIONS; DASA INVESTMENTS LLC C/O FAMILY OFFICE SOLUTIONS; LAKOFF, DAVID E.; LEES, DAVID; O'REILLY, DAVID; OKST, DAVID; KEHLER, DEAN C.; KOBAK, DOROTHY; CRAWFORD, ELIZABETH; ALTMANN, ERIC; JOR, GERALD R, JR.; GRANDPRIX LIMITED C/O LOEB BLOCK & PARTNERS L.P.; RAUTENBERG, H.W.; HARPEL, JAMES W.; WU, JASPER; PEISACH, JAIME; LG MANAGEMENT LLC.; LTE PARTNERS; RAUTENBERG, MARK; PINTO, MAURICE; MEYTHALER INVESTMENT PARTNERS LLC; MASELLI, MICHAEL; GYENES, PETER; GINTHER, RAYMOND; BERKELEY, RICHARD M.; MERCER, ROBERT; ROLA INVESTMENTS LLC C/O FAMILY OFFICE SOLUTIONS; SOS & CO.; BARLE, STANKO; STRAUS, SANDOR; MIROCHNIKOFF, SYLVAIN; MERCER, REBEKAH; TOPSPIN SFC HOLDINGS LLC.; BARTON, WESLEY W.; ZUG VENTURES LLC C/O KATHY COOK, FUSION GROUP; ZUCKER, CHARLES; COLEMAN, ROGER T.; COLEMAN, MARGARET E.; COLEMAN, THERESA M.; COLEMAN, JOHN T.; PERLBINDER, STEPHEN
To: SECURITY FIRST CORP.
Reel/Frame 061578/0505 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 29, 2022
From: SECURITY FIRST CORP
To: SECURITY FIRST INNOVATIONS, LLC
Reel/Frame 061262/0865 →
PATENT SECURITY AGREEMENT Recorded Jun 24, 2016
From: SECURITY FIRST CORP.
To: GYENES, ANDY; AUBER INVESTMENTS LTD.; SIMONS, BARBARA; BLT1; O'REILLY, COLIN; COOPER ROAD LLC; COYDOG FOUNDATION; DASA INVESTMENTS LLC; LAKOFF, DAVID E; LEES, DAVID; O'REILLY, DAVID; OKST, DAVID; KEHLER, DEAN C; KOBAK, DOROTHY; CRAWFORD, ELIZABETH; ALTMANN, ERIC; JORDAN, GERALD R, JR; GRANDPRIX LIMITED; RAUTENBERG, H.W.; HARPEL, JAMES W.; WU, JASPER; PEISACH, JAIME; LG MANAGEMENT LLC; LTE PARTNERS; RAUTENBERG, MARK; PINTO, MAURICE; MEYTHALER INVESTMENT PARTNERS LLC; MASELLI, MICHAEL; GYENES, PETER; GINTHER, RAYMOND; BERKELEY, RICHARD M; MERCER, ROBERT; ROLA INVESTMENTS LLC; SOS & CO.; BARLE, STANKO; STRAUS, SANDOR; MIROCHNIKOFF, SYLVAIN; MERCER, REBEKAH; TOPSPIN SFC HOLDINGS LLC; BARTON, WESLEY W; ZUG VENTURES LLC; ZUCKER, CHARLES; COLEMAN, ROGER T.; COLEMAN, MARGARET E.; COLEMAN, THERESA M.; COLEMAN, JOHN T.; PERLBINDER, STEPHEN
Reel/Frame 039153/0321 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 5, 2013
From: BONO, STEPHEN C.; GREEN, MATTHEW D.; LANDAU, GABRIEL D.; ORSINI, RICK L.; O'HARE, MARK S.; DAVENPORT, ROGER S.
To: SECURITY FIRST CORP.
Reel/Frame 030553/0381 →